GNU bug report logs - #17625
details of package signing mechanism

Previous Next

Package: emacs;

Reported by: Eric Abrahamsen <eric <at> ericabrahamsen.net>

Date: Thu, 29 May 2014 03:12:01 UTC

Severity: important

Tags: security

Found in version 24.4.50

Done: Stefan Monnier <monnier <at> iro.umontreal.ca>

Bug is archived. No further changes may be made.

Full log


View this message in rfc822 format

From: Glenn Morris <rgm <at> gnu.org>
To: Stefan Monnier <monnier <at> iro.umontreal.ca>
Cc: 17625 <at> debbugs.gnu.org
Subject: bug#17625: 24.4.50; All installed packages marked "unsigned", no archive listed
Date: Tue, 24 Jun 2014 01:56:56 -0400
Stefan Monnier wrote:

> SSH does it this way and nobody really complains loudly about it:
> basically, you have to trust the initial connection, but not subsequent
> ones (since you already have the key at that point).

OK, true.
I guess yum and apt basically work the same.
IIUC, you get a default key(s) when you first install the OS.
This is then used to check subsequent updates.
So you have to trust your initial download of the base OS.




This bug report was last modified 10 years and 236 days ago.

Previous Next


GNU bug tracking system
Copyright (C) 1999 Darren O. Benham, 1997,2003 nCipher Corporation Ltd, 1994-97 Ian Jackson.